NDAA Compliant Cameras: You May Not Need to Replace Yours
The FCC closed its legacy import loophole on 16 July 2026, and within a week the phrase NDAA compliant cameras was back at the top of every integrator’s quote. Nothing in that rule switches off an installed camera. Before you sign a replacement order, work out whether the obligation reaches you at all, and whether the project it is holding up actually needs to wait.
What changed on 16 July 2026
The FCC’s Public Safety and Homeland Security Bureau and its Office of Engineering and Technology released Public Notice DA 26-635 on 26 June 2026. It was published in the Federal Register on 6 July and took effect ten days later.
What it does is narrow. Equipment added to the FCC’s Covered List in 2024 or earlier, and authorised before the November 2022 cut-off, can no longer be imported into the United States or marketed here. Until this notice, a model authorised before that cut-off could keep arriving indefinitely, which is why a decade-old design was still turning up on quotes in 2026. That gap is now closed.
What it does not do is equally specific. The Commission revoked no equipment authorizations. It limited them. The machinery for that came from an order adopted on 29 October 2025 and codified at 47 CFR 2.939(e), which lets the Bureau stop future importation and marketing of covered equipment while the underlying authorization stands. The procedure requires a public notice and at least thirty days of comment before anything happens. The Federal Register notice then states the consequence directly: equipment you already possess, legally purchased and still holding an authorization, may continue in use.
One boundary in the notice is easy to miss. It reaches equipment added to the Covered List in 2024 or earlier, and the list has kept growing since: foreign-produced uncrewed aircraft systems and the communications and video surveillance equipment named in section 1709 of the fiscal 2025 National Defense Authorization Act were added on 22 December 2025, routers on 23 March 2026, and power inverters and advanced robotic devices on 28 July 2026. None of those are covered by the July prohibition. The Bureau opened a separate proceeding for them the following day, in Public Notice DA 26-742 on 17 July 2026, proposing the same treatment and saying the same thing about use: importation and marketing would be prohibited, and equipment already in users’ hands would remain authorised. That one is a proposal out for comment, not a rule.
Current as of 12 August 2026. This is an open docket with follow-on proceedings; check the FCC’s Covered List page before relying on any date here.
What “NDAA compliant cameras” actually means
NDAA compliant cameras are cameras containing no equipment produced by the manufacturers named in Section 889 of the fiscal 2019 National Defense Authorization Act: Huawei, ZTE, Hytera, Hangzhou Hikvision and Dahua, or their subsidiaries and affiliates. The phrase is a procurement term. It describes who built the hardware, not how well the hardware works or how securely it is configured.
It is also a narrower claim than it sounds, because the FCC’s Covered List and Section 889’s list of manufacturers are two different documents and only the second is what the phrase refers to. The Covered List carries those five manufacturers, and also Kaspersky, several international telecommunications carriers, foreign-produced drones and routers, power inverters, and advanced robotic devices. A supplier writing “NDAA compliant” on a quote is answering a question about five named manufacturers. It is not a statement about the Covered List as it stands today.
There is a qualifier in the Covered List that almost no product page reproduces. Video surveillance equipment from Hytera, Hikvision and Dahua was added on 12 March 2021, and it sits on the list when used for public safety, security of government facilities, physical security surveillance of critical infrastructure, and other national security purposes. The same wording governs the federal procurement clause at FAR 52.204-25. Telecommunications equipment from Huawei and ZTE carries no such qualifier. The video surveillance entries do.
That third purpose has been unsettled for two years. The D.C. Circuit vacated the FCC’s definition of critical infrastructure in 2024, calling it unjustifiably broad, and sent it back to the Commission. With no replacement definition in force, the June 2026 notice suspended the import and marketing prohibition for that one purpose until the FCC adopts one. On 22 July 2026 it did, taking the definition Congress already wrote into the USA PATRIOT Act: systems and assets so vital that their incapacity would have a debilitating impact on security, national economic security, or national public health and safety. The suspension lifts when that definition takes effect.
Import and marketing is not use
Three groups read the same headline and reach different conclusions, and only one of them is under a deadline.
The FCC limited an authorization. It did not switch off a camera.
Importers and resellers are directly affected: the covered models cannot lawfully come in or be sold. Federal contractors have a separate, older obligation that has nothing to do with the July date. Everyone else — the private warehouse, the yard, the plant, the distribution centre — has a supply question, not a compliance emergency. When the current stock of covered spares runs out, replacements will have to come from somewhere else. That is a procurement timeline, not a removal order.
| Instrument | What it prohibits | Who it binds |
|---|---|---|
| FCC Covered List (video surveillance entries added 12 Mar 2021) | Nothing on its own — it designates equipment and scopes it by purpose of use | No one directly |
| Secure Equipment Act rules (from 11 Nov 2022) | New FCC equipment authorizations for covered models | Manufacturers seeking authorization |
| Public Notice DA 26-635 (effective 16 Jul 2026) | Importation and marketing of previously authorised covered models | Importers, distributors, resellers |
| Section 889 / FAR 52.204-25 (from 13 Aug 2020) | Use of covered equipment as a substantial or essential component of any system | Federal agencies and their contractors |
Read the last row carefully, because it is the one that reaches use. Section 889(a)(1)(B) bars an agency from contracting with an entity that uses covered equipment, and that prohibition follows the contractor rather than the contract: the camera on a warehouse wall counts even if no federal work happens in that warehouse. If you hold federal contracts, or intend to bid, this is your obligation and it has been in force since August 2020.
Why the replace-everything reflex costs more than it fixes
The instinct to rip the fleet out is not irrational, and the people acting on it usually have a real prompt. A prime contractor pushed a flow-down clause. An insurer’s questionnaire asked about Chinese-manufactured equipment. A large customer’s vendor security review flagged it. Diligence ahead of a sale raised it. Those are legitimate reasons to replace hardware, and they are all commercial or contractual reasons rather than FCC ones.
The problem is what the reflex does to sequencing. A fleet refresh is a capital line, a procurement cycle, and weeks of ladder work across every site. Everything downstream of the cameras waits for it. The analytics project that would have told you something useful about the loading bay this quarter now sits behind a hardware program that finishes next year, and the intervening months produce exactly as much operational insight as the years before them did: none.
It also solves less than people expect. Replacing a covered camera with a rebranded unit built by the same original manufacturer changes the label and nothing else. And a fleet refresh chosen purely on brand compliance tends to optimise for the wrong variable, because the specification that decides whether analytics work on a camera is placement and pixel density, not the badge. That is the argument for treating the two decisions separately, which is also why you don’t need new cameras to get AI video analytics in the first place.
How to separate the camera decision from the analytics decision
Four steps, in this order. The first two are free and usually end the conversation.
Establish whether the equipment is covered at all
Pull the FCC ID from a sample of each model in the fleet. It is printed on the camera label and repeated in the device’s own web interface. That ID identifies the grantee of the equipment authorization, which is the manufacturer of record regardless of whose logo is moulded into the housing.
Then apply the purpose qualifier. For video surveillance equipment the Covered List designation attaches to use for public safety, security of government facilities, physical security surveillance of critical infrastructure, and other national security purposes. A camera watching a dock door at a third-party logistics site is a different case from one watching a substation fence. If your operation falls inside one of the sixteen critical infrastructure sectors, treat the qualifier as satisfied and move on; if it plainly does not, record the reasoning and the date, because that record is what you will be asked for later.
Establish whether you have a use obligation
This is a yes or no question with a short decision path. Do you hold a federal prime contract or subcontract? Do you intend to bid for one? Has a customer flowed FAR 52.204-25 down to you in writing? If all three answers are no, you have no federal use obligation, and the July 2026 rule gives you a supply constraint rather than a removal deadline.
If any answer is yes, the obligation is real, it predates this year’s news by six years, and the exception and waiver paths are narrow. That is a question for counsel and for your contracting officer, not one to settle from a vendor’s compliance page.
Deal with the OEM problem before you buy anything
A large share of the market is built by a small number of factories. Rebranding is normal and legal, and it is also the reason a compliance-driven refresh can end where it started.
Ask for the FCC ID of every proposed model in writing, before purchase, and check it yourself rather than accepting a compliance declaration. Firmware gives a second signal: web interface layout, default port assignments, and the manufacturer string returned by an ONVIF device information query frequently match the original builder rather than the brand on the box. If a supplier will not put the FCC ID in the quote, that is your answer.
Sequence the refresh so it does not hold the analytics project hostage
Analytics that reads a standard RTSP or ONVIF stream does not care which company assembled the camera producing it. That is the practical consequence of the separation, and it runs in both directions.
It means an analytics deployment made this quarter survives a hardware refresh made in two years, because the software reads whatever feed exists at the time. It also means the refresh does not have to complete before the analytics start. Run the two as independent programs with independent budgets: replace cameras when the contract, the insurer, or the end of the spares supply requires it, and connect analytics to the fleet you have now. The one dependency worth respecting is the reverse of the usual assumption — knowing which detections you actually want, and at what pixel density, is useful input into the camera specification when the refresh does happen. Working out what existing cameras can already tell you is therefore a reasonable thing to do first, not last.
Where Nsightify fits
Nsightify reads the IP and CCTV cameras a site already operates. No camera is replaced to connect it, and the analysis is indifferent to the manufacturer, because what it consumes is a standard video stream. Detections such as intrusion into a restricted zone, loitering, blocked exits and forklift–pedestrian proximity produce real-time alerts on the fleet as it stands today, and on whatever fleet replaces it later. Deployment is either Nsightify Cloud or a Zero Trust on-premises option for organisations whose footage cannot leave their own network, which is a common constraint in exactly the sectors where the covered-equipment question arises.
To be clear about what this is not: Nsightify does not audit a camera fleet, does not determine whether a given model is covered equipment, and resolves nobody’s Section 889 obligations. Those are questions for your contracting officer and your counsel.
The technical limits are worth stating too. Camera-based detection depends on sightlines, lighting, and where a camera was mounted, which was almost never for analytics. Occlusion in a racked aisle or behind a parked trailer is real. Resolution at the distance that matters sets a floor on what can be detected reliably. Those constraints apply to the cameras you own and to any cameras you buy, which is one more reason the real-time monitoring question deserves its own answer rather than being folded into a procurement decision about brands.
Questions operators are asking
Do I have to replace my Hikvision or Dahua cameras?
Not because of the July 2026 FCC rule. That rule prohibits importing and marketing previously authorised covered equipment. It does not revoke the authorizations already granted, and the Federal Register notice is explicit that equipment legally purchased and still holding an authorization may continue to be used. A replacement obligation, where one exists, comes from a federal contract clause, an insurer, or a customer requirement, not from the FCC.
Are my existing cameras still legal to use?
For a private commercial operator with no federal contract, yes. Nothing in the June 2026 Public Notice or its Federal Register publication reaches the operation of installed equipment. The Commission limited the scope of existing equipment authorizations under 47 CFR 2.939(e) precisely so it could stop imports without revoking authorizations and forcing equipment off the air.
What does NDAA compliant mean for cameras?
It means the camera contains no equipment produced by the manufacturers named in Section 889 of the fiscal 2019 National Defense Authorization Act: Huawei, ZTE, Hytera, Hangzhou Hikvision and Dahua, or their subsidiaries and affiliates. It is a procurement term describing who made the hardware. It says nothing about image quality, cyber hygiene, or whether the camera suits your site.
Does Section 889 apply to private companies?
Only through federal contracting. Section 889(a)(1)(B) prohibits an executive agency from contracting with an entity that uses covered equipment as a substantial or essential component of any system, and that reaches use outside the contract as well as inside it. A private company with no federal contracts and no intention of bidding for one is not bound by it.
How do I tell if a camera is an OEM rebrand?
The brand on the housing is not evidence. Check the FCC ID printed on the label against the FCC equipment authorization database, which names the grantee rather than the reseller. Firmware fingerprints help too: the web interface layout, default port assignments and ONVIF device information often match the original manufacturer. Ask your integrator for the FCC ID in writing before purchase.
What to check before your next camera quote
Sample the FCC IDs across your fleet and find out what you actually own. Write down whether your operation falls inside the purpose qualifier, and date it. Answer the federal contracting question once, in writing, so it stops being reopened every time a headline lands. If the answer is that nothing forces your hand, you have a spares-supply plan to make over the next few years rather than a capital program to fund this one.
Then ask the separate question, the one the hardware debate has been standing in front of: whether anyone is watching the feeds those cameras already produce. If connecting analytics to the fleet you have today is the part that keeps getting deferred, talk to us about camera and system integration.
Keep reading:
More on this from Nsightify: AI video analytics on existing IP and CCTV cameras.
See Nsightify in Action
We're onboarding a limited number of pilot partners. If you're an operations or security leader in construction, warehousing, or manufacturing — let's talk.